Earlier quoted context omitted.
Because a Windows zero-day is a major risk to our economic system as our business and governments infrastructures run on MS products for the most part. OSX just doesn't have that level of install base and for the most part its installed on consumer/residential equipment. Heck, most OSX shops I've been part of have bog standard Windows AD on the back-end. Windows, good or bad, is everywhere that matters. Google seems…
Then perhaps MS ought to shorten its bug fixing period. Three months is quite a long time to find a bug, fix it, and run extensive tests. What good is a fixed time period if you're willing to extend it just because one company can't pull their shit together? As for the Kaminsky DNS bug, it was leaked more than a solid week ahead of the time he intended to release it. Sure, patches had already been released, but how a…
Google discloses another Windows security issue after deadline exceeded
101–110 of 152 posts
Re: Google discloses another Windows security issue after deadline exceeded
#102Re: Google discloses another Windows security issue after deadline exceeded
#103Earlier quoted context omitted.
Then again, 90 days contains 2.5 of their fix cycles. If the vulnerability really is serious, and they can't fix it in that time line, they should exit the business.
Google roughly supports one version of their product on 2 OSs. Microsoft supports all versions of all their products for 10years+ after release, integrated with a combination of all other products they have shipped in that same time-frame. Needless to say, Microsoft needs to do more QA on their bug-fixes before they can safely release it to all customers without the risk of causing new issues. It's easy for Google to…
IIRC Microsoft also releases pre-versions of their patches to select customers so sysadmins can test the patch doesn't cause issues on their deployments.
Re: Google discloses another Windows security issue after deadline exceeded
#104In another news, google stop fixing security bugs which cover 60% of the current android users (4.3 or older). Not saying microsoft is right, but they just dropped windows xp support last year (that is >10 years of support). [1] http://arstechnica.com/security/2015/01/google-wont-fix-bug-...
Re: Google discloses another Windows security issue after deadline exceeded
#105In another news, google stop fixing security bugs which cover 60% of the current android users (4.3 or older). Not saying microsoft is right, but they just dropped windows xp support last year (that is >10 years of support). [1] http://arstechnica.com/security/2015/01/google-wont-fix-bug-...
Little known fact: since lollipop, the webview is now upgradeable: https://developer.android.com/about/versions/lollipop.html#W... . So in two years, it will be a thing of the past. And regressions of old-apps using new-webview will be a real issue.
AHAHAHAHAHAHAHAHAHAHAHA
Re: Google discloses another Windows security issue after deadline exceeded
#106Earlier quoted context omitted.
Then perhaps MS ought to shorten its bug fixing period. Three months is quite a long time to find a bug, fix it, and run extensive tests. What good is a fixed time period if you're willing to extend it just because one company can't pull their shit together? As for the Kaminsky DNS bug, it was leaked more than a solid week ahead of the time he intended to release it. Sure, patches had already been released, but how a…
Everybody is saying that 90 days is too much, even at MS' scale. So, taking into account that everybody seems to know very well what MS has to support, what is a good number of days to finish all the work that needs to be done?
When it actually affects them, they aren't hesitant to do whatever the hell it takes, with no regards as to the consequences for others, with zero warning at all, as was shown during the whole fiasco when they effectively took down NoIP's services. Meanwhile, when Google holds them to a perfectly reasonable deadline, for the extremely valid reason that bugs should be fixed on time, Google is evil?
Given their scale, they can afford to dedicate larger teams of people to the task of fixing security vulnerabilities. They can afford to hire independent security researchers and whatnot to help them find and fix such vulnerabilities.
If they need to break some third-party application in fixing a security vulnerability, that's okay. Because that application can also be fixed by its developer, and security needs come ahead of an app here or an app there. Besides, it isn't as if users of Microsoft's products are not used to the concept of having stuff break all the time anyways.
Have you noticed how quickly MS starts releasing patches and updates when a 0day comes out? That shows that they are clearly capable of doing whatever they need to do pretty damn quickly. They just don't do that with all security vulnerabilities, due to "business reasons", and as a result their customers suffer.
Re: Google discloses another Windows security issue after deadline exceeded
#107I ended up halting development of my project while I waited for Adobe, to the point where I no longer wanted to work on it. I had stopped for too long and I didn't want to dig anything else up. Having no legal type knowledge myself or knowing anyone who could offer such advice, I was also too concerned to reveal anything for fear or any legal reprise.
So, the threat of security disclosure is warranted to pressure others into putting in the effort. However, the impact of the disclosure should be considered. If it will seriously affect others (who aren't responsible for the fix) and put them at risk, there should be the flexibility there to work with them on a deadline.
Re: Google discloses another Windows security issue after deadline exceeded
#108Earlier quoted context omitted.
I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this. Maybe there's a similar story with OS X, but there doesn't seem to be a public record…
> others that Microsoft would just put off fixes forever if Google didn't do this. People wouldn't think that if MS didn't have a long history of doing exactly that.
Re: Google discloses another Windows security issue after deadline exceeded
#109This could end up going very badly for customers at some point in the near future. Could you imagine if google had published POC code for the SCHANNEL bug that came out lat year? You would have seen worms and new botnets immediately. That doesn't really help the situation. If they've committed to a fix, let them get it out before the public disclosure.
In the end, MS has a support task that is unlike anything else in the tech industry. If they are trying to do the right thing, and they have really improved here, why beat them over the head with it?
Re: Google discloses another Windows security issue after deadline exceeded
#110Earlier quoted context omitted.
Even if we're talking about such a massive roll-out to millions of machines, with various versions of the OS running on various hardware? I don't know how easy or not the actual patch is to produce, but it's not out of the realm of possibilities that they did run into a compatibility issue that they wanted more time to sort out. Think of the outcry and damage to their business if they rolled out a patch that accident…
Yes, even then. Imagine if the bug had been found by security researchers who believe in full disclosure. You think it's reasonable for Microsoft to allow dozens of rootkits and viruses to proliferate for more than three months, for botnets to grow to hundreds of millions in size? Microsoft's release process is broken.